What the vulnerability does
01Description
Improper Neutralization of Formula Elements in a CSV File vulnerability in BestWebSoft Post to CSV by BestWebSoft.This issue affects Post to CSV by BestWebSoft: from n/a through 1.4.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Improper Neutralization of Formula Elements in a CSV File vulnerability in BestWebSoft Post to CSV by BestWebSoft.This issue affects Post to CSV by BestWebSoft: from n/a through 1.4.0.
Explanation of Vulnerability in Simple Terms
Post to CSV by BestWebSoft versions up to 1.4.0 contain a vulnerability that allows an attacker to read or modify limited data on the site through a network-based attack. The vulnerability requires user interaction—typically the victim must click a malicious link or visit a crafted page. The impact is limited to low-level information disclosure and minor data modification.
What an attacker can do
Read or modify limited data on the site by tricking a user into clicking a malicious link.
Potential impact on your site
Users' data could be exposed or altered if they interact with attacker-controlled content while logged in.
Conditions required to exploit
No authentication required, but the victim must click a link or visit a page controlled by the attacker.
Key dates
External resources
Related vulnerabilities